arrow
返回

PrivGuard: Protecting Sensitive Kernel Data From Privilege Escalation Attacks

delete2018-01-01
delete14
delete
OA
AI
羌
羌卫中 (Weizhong Qiang) *
J
Jiawei Yang
金
金海 (Hai Jin)
X
Xuanhua Shi
DOI:10.1109/ACCESS.2018.2866498delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Kernels of operating systems are written in low-level unsafe languages, which make them inevitably vulnerable to memory corruption attacks. Most existing kernel defense mechanisms focus on preventing control-data attacks. Recently, attackers have turned the direction to non-control-data attacks by hijacking data flow, so as to bypass current defense mechanisms. Previous work has proved that non-control-data attacks are the critical threat to kernels. One of the important purposes of these attacks is to achieve privilege escalation by overwriting sensitive kernel data. The goal of our research is to develop a lightweight protection mechanism to mitigate non-control-data attacks that compromise sensitive kernel data. We propose an approach that enforces data integrity of sensitive kernel data by preventing the illegal write to these data to mitigate privilege escalation attacks. The main challenge of the proposed approach is to validate the modification of sensitive kernel data at runtime. The validation routine must verify the legitimacy of the duplicated sensitive data and ensure the credibility of the verification. To address this challenge, we modify the system call entry point to monitor the change of the sensitive kernel data without any change to Linux access control mechanism. Then, we use stack canaries to protect the duplication of sensitive kernel data that are used for integrity checking. In addition, we protect the integrity of sensitive kernel data by forbidding illegal updates to them. We have implemented the prototype for Linux kernel on Ubuntu Linux platform. The evaluation results of our prototype demonstrate that it can mitigate privilege escalation attacks and its performance overhead is moderate.
Keyword:
Kernel
non-control-data
credential
privilege escalation
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

暂无机构信息
引用论文

引用论文

err分享
err收藏
Functioning of intertidal flats inferred from temporal and spatial dynamics of O2, H2S and pH in their surface sediment
err2009-01-30
err0
errOAAI
errStefan Jansen; Eva Walpersdorf; Ursula Werner; Markus Billerbeck; Michael E Böttcher; Dirk de Beer
err分享
err收藏
Effects of Elevated Peroxidase Levels and Corn Earworm Feeding on Gene Expression in Tomato
err2012-11-08
err0
PREAI
errHideaki Suzuki; Patrick F. Dowd; Eric T. Johnson; Sue M. Hum-Musser; Richard O. Musser
err分享
err收藏
Hierarchical Morphology-Guided Tooth Instance Segmentation from CBCT Images
err2021-06-14
err0
PREAI
errZhiming Cui; Bojun Zhang; Chunfeng Lian; Changjian Li; Lei Yang; Wenping Wang; Min Zhu; Dinggang Shen
err分享
err收藏
Accurate and efficient exploit capture and classification
err2016-09-13
err6
PREAI
errDing, Yu; Wei, Tao; Xue, Hui; Zhang, Yulong; Zhang, Chao; Han, Xinhui
err分享
err收藏
err分享
err收藏
学者 查看更多内容